Unauthenticated Vulnerability in Oracle Agile Engineering Data Management Product
CVE-2026-61186

9.4CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61186?

A vulnerability exists in Oracle's Agile Engineering Data Management, specifically in version 6.2.1, which permits an unauthenticated attacker with network access to exploit the system via HTTP. Successful exploitation may lead to unauthorized creation, deletion, or modification of critical data. Moreover, it gives attackers unauthorized read access to sensitive data and the ability to cause significant disruption or crashes of the service, potentially leading to a denial of service scenario. Users are advised to promptly review the relevant security advisory from Oracle.

Affected Version(s)

Oracle Agile Engineering Data Management 6.2.1

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.